Cox Automotive is hiring an onsite Lead Cybersecurity Detection Engineer to strengthen detection across enterprise systems and customer environments. In this role, you will help advance the Detection Engineering team by designing and operating enterprise-grade detective capabilities, including AI-driven detection and automation, while partnering closely with Incident Response, Threat Intelligence, and Vulnerability Management to expand coverage and improve outcomes.
What you’ll do
- Act as a senior technical lead for detection engineering, building and maintaining detective solutions that protect Cox Automotive’s internal systems and domestic and international businesses.
- Contribute to the Detection Engineering strategy, roadmap, and objectives, helping drive execution across the team.
- Architect and deploy agentic AI systems to autonomously detect, analyze, and respond to security threats across enterprise infrastructure.
- Design multi-agent frameworks for threat hunting, incident investigation, and attack pattern recognition.
- Develop self-improving detection systems that learn from investigations and enhance detection rules and playbooks over time.
- Implement advanced detection techniques using SIEM, EDR, and SOAR platforms.
- Create custom detection rules and automated remediation playbooks and alerts aligned to Cox Automotive’s enterprise and customer threat landscape.
- Use MITRE/ATLAS frameworks to assess detection coverage and close gaps.
- Monitor, optimize, and continuously improve detection systems for performance, scalability, and effectiveness.
- Collaborate with the Threat Detection and Response team to improve identification, management, and response capabilities.
- Validate detections through attack simulation testing and support purple teaming exercises with the Vulnerability Management team.
- Manage SIEM/Data Lake data management and log ingestion infrastructure in collaboration with Cyber Defense Engineering counterparts.
- Evaluate, validate, tune, and sunset detections as needed.
- Maintain operational guidelines, diagrams, and documentation for security detection and response activities.
- Provide off-hour support as needed for security administration, detection, and response activities.
- Partner with Incident Response to accelerate threat identification and containment by building detection logic during incidents.
- Improve detection and response processes based on lessons learned from incidents, and incorporate threat intelligence to proactively mitigate risk.
- Identify emerging threat vectors and integrate them into detection strategies.
- Work with other Cybersecurity, Engineering, and Product teams to deploy detection and response solutions, including customer-focused implementations.
- Communicate detection capabilities, findings, and technical recommendations to technical and non-technical stakeholders, escalating to leadership as required.
- Design and implement processes aligned to regulatory requirements and industry standards such as GDPR, PCI-DSS, and NIST.
- Maintain documentation of detection use cases, processes, and configurations.
What you bring
- Bachelor’s degree in Computer Science or a related discipline and 6+ years of industry related professional experience.
- Multi-cloud security experience (AWS, Azure, GCP).
- Experience with AI/ML frameworks and prompt engineering for security applications.
- Expert level knowledge of Detection Engineering.
- Strong experience in information security, network security, security monitoring, and Incident Response.
- Strong experience developing SIEM/SOAR detection and automation use cases.
- Working experience with security technologies and services including threat intelligence, firewalls, SASE, IPS, endpoint security, DLP, SIEM/SOAR, and Data Lakes.
- Expert level knowledge of the attack kill chain and diamond model.
- 3+ years experience in a cyber defense role.
Tools and technologies
SIEM, EDR, SOAR, AI/ML, prompt engineering, MITRE, ATLAS, AWS, Azure, GCP, threat intelligence, firewalls, SASE, IPS, endpoint security, DLP, Data Lakes
Benefits
- Health care insurance (medical, dental, vision)
- Retirement planning (401(k))
- Paid days off (sick leave, parental leave, flexible vacation/wellness days, and/or PTO)
Preferred qualifications
- OSCP, GSEC, GCIA, GFE, GCFA, CISA, CISSP, CISM, or CIA certification(s)
- Dev Ops / Engineering / Network / System Administration experience
- Experience developing customer-focused detection and response systems
Location: Atlanta, GA (onsite)